google/exposure-notifications-verification-server

google/exposure-notifications-verification-server

Releases98
Frequency1 week 3 days
Last Release
Stars238
Verification component for COVID-19 Exposure Notifications.

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM5.8 MEDIUM

An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1.2 or greater.

6.3 MEDIUM6.5 MEDIUM

A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs due to insufficient checks on the allowed set of permissions. The new user creation event would be captured in the Event Log.